CVE-2026-17042

IBM Power Systems Firmware FW950.00 through FW950.H2, OP940.00 through OP940.a1 (Power9), and OP940.00 - OP940.81 (Power HMC) is affected by a vulnerability in host firmware NVRAM parsing. An attacker with root access to a guest partition on an OpenPOWER system can write a specially crafted NVRAM image, causing the host firmware boot stage to crash with possible memory corruption. This condition persists until operator intervention — clearing NVRAM via the service processor — to restore normal operation. This vulnerability only affects OpenPOWER systems; systems running PowerVM are not affected. Successful exploitation results in an integrity and availability impact to the managed system.
References
Link Resource
https://www.ibm.com/support/pages/node/7283240 Vendor Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:ibm:power_system_s922_\(9009-22g\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_s922_\(9009-22g\):-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:ibm:power_system_h922_\(9223-22s\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_h922_\(9223-22s\):-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:ibm:power_system_s914_\(9009-41g\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_s914_\(9009-41g\):-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:ibm:power_system_s924_\(9009-42g\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_s924_\(9009-42g\):-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:ibm:power_system_h924_\(9223-42s\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_h924_\(9223-42s\):-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:ibm:power_system_e950_\(9040-mr9\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_e950_\(9040-mr9\):-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:ibm:power_system_e980_\(9080-m9s\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_e980_\(9080-m9s\):-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:ibm:power_system_ac922_\(8335-gth\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_ac922_\(8335-gth\):-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:ibm:power_system_ac922_\(8335-gtx\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_ac922_\(8335-gtx\):-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:ibm:power_hardware_management_console_\(7063-cr2\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_hardware_management_console_\(7063-cr2\):-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-08-19 20:17

Updated : 2026-08-25 13:14


NVD link : CVE-2026-17042

Mitre link : CVE-2026-17042

CVE.ORG link : CVE-2026-17042


JSON object : View

Products Affected

ibm

  • power_hardware_management_console_\(7063-cr2\)_firmware
  • power_system_e950_\(9040-mr9\)
  • power_system_ac922_\(8335-gth\)_firmware
  • power_system_e980_\(9080-m9s\)
  • power_system_s922_\(9009-22g\)_firmware
  • power_system_ac922_\(8335-gtx\)_firmware
  • power_system_s924_\(9009-42g\)
  • power_system_s924_\(9009-42g\)_firmware
  • power_system_s914_\(9009-41g\)
  • power_system_s914_\(9009-41g\)_firmware
  • power_system_h924_\(9223-42s\)_firmware
  • power_system_h922_\(9223-22s\)
  • power_system_s922_\(9009-22g\)
  • power_system_ac922_\(8335-gth\)
  • power_system_e950_\(9040-mr9\)_firmware
  • power_system_e980_\(9080-m9s\)_firmware
  • power_system_h922_\(9223-22s\)_firmware
  • power_system_ac922_\(8335-gtx\)
  • power_hardware_management_console_\(7063-cr2\)
  • power_system_h924_\(9223-42s\)
CWE
CWE-125

Out-of-bounds Read